How to Secure Your Wordpress Blog From Brute Force Attacks?
Securing Wordpress Site From Hacking Attempts
A major concern with most WordPress users is the safety of their sites. Wordpress is a much-liked platform for blogging as it is SEO friendly. However, WordPress sites also are more vulnerable to hacker attacks. No matter how much effort you have put to secure your site, there are evil guys around waiting to steal your site. These guys are masters of their trade. They are so smart that an ordinary blogger may not even come to know even after being hacked. As the popular saying goes, prevention is better than cure. Rather than putting your sites to risk and then spending time and money in recovering the sites, it’s worth putting some efforts to ensure the security of your sites.
Over 30,000 WordPress sites have already been hacked and taken control over by the bad guys. The hackers may use these sites to send spam emails, crash servers, make money, plant further virus and so much more. For the past one month or so, brute force attacks have increased to a considerable extent. Thousands of bloggers have lost their sites, personal details compromised and even lost their hosting accounts. Just because, you have not been hit does not mean that you are safe. Even if you manage to survive the hacking attempts, you may still end up paying an extra traffic bill to your hosting company because of their numerous attempts to break into your website or blog. Though you may not be able to make your WordPress sites 100% hacker proof, you can certainly reduce the chances of the sites getting hacked. This can be done by hiding the WordPress installation from hackers.
My first WordPress site got hacked and some malicious code was installed by the hackers within 3 months of starting it. One day I found my hosting account suspended and I could not log in to my site. When I contacted the hosting company, they treated me as if I am some criminal. However, they helped me recover my domain to the starting state, but all my data was lost. I had written over 90 blog posts and did not have any backup. The hosting company further warned me that in the event of it happening again, I would lose the hosting account. I never felt insulted that much in my whole life and decided that I need to take steps to secure my domains. I read all stuff I could get on WordPress security and even got many premium plugins to protect my blogs. My efforts paid off, and I managed to reduce the internet footprints to prevent brute force attacks from hackers. The hackers are a smart lot and may come up with new ways of breaking into sites, so it is worth taking precautions to stop them on their track. If you have an online WordPress sites empire or manage WordPress based clients sites, you need to take steps to protect your sites.
How to Protect Your Wordpress Site From Hackers?
Do you want to secure your WordPress sites from hackers? Given below are some steps you can take to ensure the security of your sites.
- Keep your computer clean: It is advisable that you have a private connection. Try not access your site from public computers. Make sure you run a virus scan on your own computer to ensure that it is clean at all times. Most hackers try to infect your computer with malicious viruses first. I advise a combination of Kaspersky internet security and Malwarebytes antI-malware pro version.
- Reliable web hosting: Get the hosting account for your WordPress sites from reliable hosting companies like Bluehost.
- Have strong user name and passwords: Your password and user name should be in a combination of capital letters, small letters, numbers, and symbols. Avoid user names like admin, user, 1, administrator and manager that are quite easy to guess. However, if you happen to have such a username you can add a new secure user with a strong password and user name and then delete the old user. For this, under users in your admin panel click on add a new user. Make sure that the user name and password comprises of at least 8 characters and use a combination of upper and lowercase letters, numbers, and symbols to create the username and password. Give admin rights to this new user. Now log out of your admin panel and log in as the new user. Go to user section and delete the old user. However, make sure that you remember your new login details. Also, avoid passwords like password and 12345.
- Themes: Use the free themes hosted by WordPress or premium themes from reputed theme makers like catch themes or woo themes. Delete the unused themes from the theme area.
- Add WordPress security plugins: Wordpress security plugins can add an extra layer of protection to your sites. Some of the best plugins you can use to secure your sites are bulletproof security, better wp security, secure WordPress, Sucuri SiteCheck malware scanner, wp security scan, login lockdown, ask apache password protect and wp- brute force. The pro or premium versions of these plugins offer better security from hackers, so I advise you to spend money on it. We spend so much money to protect our physical assets by investing in lockers, security personnel, and security devices. Why not get the best protection for our virtual real estate? Just adding the plugins is not enough, activate them and configure them correctly. However, keep checking your sites as you make changes as some changes may break the site. It is advisable to install these plugins at the time of WordPress installation itself. If it is an existing site, make sure you do a backup before configuring the plugins as some changes may not be compatible with your WordPress theme, the plugins you use or your server configuration. Configuring the plugins is quite a tedious task. If you need assistance configuring, I would happily do it at a reasonable price.
- Change file permissions: Use FileZilla FTP software to access your site and change ht access file, wp-blog-header.Php, wp-config.Php and index.Php file permission to 404. Also, change wp-admin and wp-content to permission 705. However, make sure use refresh the site every time a change is made to ensure that it is not broken. Now delete readme.Html from public HTML folder. Next, go to the wp-config folder and delete install.Php and install-helper.Php.
- Keep your WordPress updated: Make sure you keep your WordPress version, plugins, and themes updated at all times. Also, try to limit the number of plugins. Also, make sure that you back up the site regularly so that you have the data to restore your site if needed. You may use wp online backup, vault press, backup buddy or wp DB backup for this purpose.
Now that, you have done the above steps you are ahead of thousands of WordPress users who do nothing to secure their sites. However, remember that your sites are still not 100% secured. You only have reduced the chances of your sites getting hacked.
Was this hub helpful to you? Feel free to share your opinions by way of comments. Liked this hub? Please feel free to share this hub link on social networking sites.
How to Secure your Wordpress Site for Free?
WordPress Security Threats and Tips by Dre Armeda of Sucuri
How to fix a Hacked Wordpress Site?
Will you spend money on the security of your Wordpress sites?
© 2013 Anamika S Jain